Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-23639

Опубликовано: 09 фев. 2024
Источник: nvd
CVSS3: 5.1
CVSS3: 7.8
EPSS Низкий

Описание

Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the Groovy language. Enabled but unsecured management endpoints are susceptible to drive-by localhost attacks. While not typical of a production application, these attacks may have more impact on a development environment where such endpoints may be flipped on without much thought. A malicious/compromised website can make HTTP requests to localhost. Normally, such requests would trigger a CORS preflight check which would prevent the request; however, some requests are "simple" and do not require a preflight check. These endpoints, if enabled and not secured, are vulnerable to being triggered. Production environments typically disable unused endpoints and secure/restrict access to needed endpoints. A more likely victim is the developer in their local development host, who has enabled endpoints without security for the s

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:objectcomputing:micronaut:*:*:*:*:*:*:*:*
Версия до 3.8.3 (исключая)

EPSS

Процентиль: 9%
0.00031
Низкий

5.1 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-15

Связанные уязвимости

CVSS3: 5.1
github
почти 2 года назад

Micronaut management endpoints vulnerable to drive-by localhost attack

EPSS

Процентиль: 9%
0.00031
Низкий

5.1 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-15